Skip to content
Security & Trust

Ex-soldier gets 70 months for extorting at least 10 tech and telecom firms

Court documents describe stolen logins, Telegram coordination and stolen data offered on criminal forums

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Ex-soldier gets 70 months for extorting at least 10 tech and telecom firms

AI-generated image for WebPulse. About our images

Key finding

Prison sentence: 70 months (Source: BleepingComputer, reporting on the U.S. Justice Department case (September 28, 2026))

What the court record says about method

Cameron John Wagenius, a 21-year-old former U.S. Army soldier, will serve 70 months in prison for breaking into and extorting at least 10 American technology and telecom companies between April 2023 and December 2024, according to BleepingComputer's September 28, 2026 report. Court documents say the group obtained the victims' network logins with SSH Brute, a tool Wagenius had a hand in building. The stolen data was then used to demand payment, offered for sale on criminal forums and put to work in other frauds such as SIM-swapping.

70 months
Prison sentence
Source: BleepingComputer, reporting on the U.S. Justice Department case (September 28, 2026)
10
Victim companies (at least)
Source: BleepingComputer (September 28, 2026)

Telegram, active duty and a two-stage plea

Court documents say Wagenius was on active Army duty when he and his accomplices stole the victims' login credentials. The group used Telegram to move stolen credentials between its members and to plan attacks. The source does not say how each victim's credentials were obtained, or that every intrusion followed the same path.

He was taken into custody in Texas in December 2024. A February 2025 guilty plea concerned AT&T and Verizon, following two charges of unlawfully transferring confidential phone records. By July 2025 the list of admitted offences had grown to include extortion connected to computer fraud, a conspiracy to commit wire fraud and aggravated identity theft.

Ransom demands, forum sales and other fraud

According to the Justice Department, victims were pressured both in private and in public. Among the forums named in those threats were BreachForums and XSS.is, where the group said it would post the stolen data. In other cases the conspirators advertised data on those forums for thousands of dollars. The department says they sold at least some of it and applied stolen data to other frauds, SIM-swapping among them.

For a budget signer, the implication is about planning scope. Incident-response plans written around a ransom demand and a payment decision may not cover a case in which the same data is offered for sale on a forum, or reused for fraud against customers. Whether your plan addresses those paths is a question for your team, not a finding from this case.

$1 million
Amount the group attempted to extort (at least)
Source: U.S. Justice Department, as quoted by BleepingComputer (September 28, 2026)

Wagenius was also ordered to pay $294,978 in restitution tied to intrusions into telecom companies' databases and the extortion that followed. The source does not present that figure as a measure of total victim losses.

Snowflake: what the source does and does not say

BleepingComputer links Wagenius to a wider case by naming two of his co-conspirators, Connor Riley Moucka and John Erin Binns. Accusations against them, made in November 2024, concern data theft on the scale of terabytes from more than 165 organisations that used Snowflake's cloud storage service. Payment was demanded for deleting the data and keeping it from being leaked. Moucka was arrested in Canada on October 30, 2024, and pleaded guilty in August 2026 to his part in the Snowflake campaign. The report says breaches linked to those attacks affected hundreds of millions of people, among them customers of AT&T, Ticketmaster, Santander and Neiman Marcus, along with several other organisations.

The source does not say how the Snowflake intrusions were carried out. It does not say they used SSH Brute, that stolen credentials were involved, or that any customer accounts lacked multi-factor authentication (MFA). It says only that Snowflake, after the breaches, announced it would enforce MFA and require passwords of at least 14 characters. Treat that as a prompt for your own review, not as a finding about Snowflake's customers.

165+
Organisations in the accused Snowflake campaign
Source: BleepingComputer (September 28, 2026)

Questions to put to your team

First, which internet-facing services in our estate still accept password-only sign-in, SSH included, and who owns that list? Second, for each third-party data platform we use, is MFA enforced by the vendor or left to our own configuration, and can we show the evidence? Third, how would we learn that credentials for our systems were circulating, and how quickly? Fourth, if our data appeared for sale on a criminal forum rather than in a ransom note, who decides our response and who is notified? Fifth, do our fraud and customer-support teams have a plan for SIM-swapping that draws on breached data?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: BleepingComputer.

Share this insight